python 3.13.13 [CVE-2026-7210] #74

Open
opened 2026-08-06 12:41:32 +00:00 by victor · 0 comments
Member

Installed: 3.13.13

CVE-2026-7210 is a security flaw in Python (xml.parsers.expat and xml.etree.ElementTree) caused by low random data (entropy) in hash protection. A bad XML file can cause high CPU use and a crash (DoS). Fix it by updating libexpat to version 2.8.0 or later and applying the official Python patch.

Update your system's libexpat library to version 2.8.0 or higher.

Installed: 3.13.13 CVE-2026-7210 is a security flaw in Python (xml.parsers.expat and xml.etree.ElementTree) caused by low random data (entropy) in hash protection. A bad XML file can cause high CPU use and a crash (DoS). Fix it by updating libexpat to version 2.8.0 or later and applying the official Python patch. Update your system's libexpat library to version 2.8.0 or higher.
victor added this to the v0.1.2 milestone 2026-08-06 12:41:32 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
MinBZK/DAWO-NixOS#74
No description provided.